Icewarp WebMail 多个 跨站脚本攻击漏洞

Icewarp WebMail 多个 跨站脚本攻击漏洞

漏洞ID 1108422 漏洞类型 跨站脚本
发布时间 2005-01-28 更新时间 2005-10-20
图片[1]-Icewarp WebMail 多个 跨站脚本攻击漏洞-安全小百科CVE编号 CVE-2005-0320
图片[2]-Icewarp WebMail 多个 跨站脚本攻击漏洞-安全小百科CNNVD-ID CNNVD-200501-313
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/25068
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200501-313
|漏洞详情
MerakMailServer是一款功能强大的邮件服务程序使用IcewarpWebMail5.3.0的MERAKMailServer7.6.0版本中的存在多个跨站点脚本漏洞。远程攻击者可以通过login.html的username参数,accountsettings_add.html的accountid参数,或者calendar.html的note、title、location字段,注入任意web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/12396/info

Multiple remote vulnerabilities reportedly affect IceWarp Web Mail. The underlying issues are due to input and access validation errors.

Multiple cross-site scripting and HTML injection vulnerabilities affect the vulnerable software. The product is also vulnerable to a file creation with arbitrary data vulnerability. Finally it is possible for an authenticated attacker to move and read arbitrary files on an affected computer with the privileges of the affected application.

An attacker may leverage these issues to move arbitrary files with the privileges of the affected server, to carry out cross-site scripting and HTML injection attacks and to create a file with arbitrary content. These issues may lead to system wide denial of service as well as other attacks. 

http://www.example.com:32000/mail/login.html?username=[xss_here]
|参考资料

来源:BID
名称:12396
链接:http://www.securityfocus.com/bid/12396
来源:XF
名称:merak-icewarp-multiple-xss(19147)
链接:http://xforce.iss.net/xforce/xfdb/19147
来源:BUGTRAQ
名称:20050128MultiplevulnerabilitiesinIcewarpWebMail5.3.0:Newholes
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=110693950205007&w;=2

相关推荐: BisonFTP超长命令远程拒绝服务漏洞

BisonFTP超长命令远程拒绝服务漏洞 漏洞ID 1203066 漏洞类型 输入验证 发布时间 2003-02-17 更新时间 2003-12-31 CVE编号 CVE-2003-1416 CNNVD-ID CNNVD-200312-213 漏洞平台 N/A…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享